The open source embeddable online markdown editor (component).

CVE History

CVEPublishedCVSS v2CVSS v3
CVE-2020-196606.1 MEDIUMN/A
Cross Site Scripting (XSS) pandao editor.md 1.5.0 allows attackers to execute arbitrary code via crafted linked url values.
CVE-2023-296416.1 MEDIUMN/A
Cross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script or HTML via crafted markdown text.
CVE-2020-196976.1 MEDIUMN/A
Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script in the <iframe>src parameter.
CVE-2020-196986.1 MEDIUMN/A
Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the editor parameter.
CVE-2019-146536.1 MEDIUM4.3 MEDIUM
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
CVE-2019-145176.1 MEDIUM4.3 MEDIUM
pandao Editor.md 1.5.0 allows XSS via the Javas&#99;ript: string.
CVE-2019-97376.1 MEDIUM4.3 MEDIUM
Editor.md 1.5.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.
CVE-2018-190566.1 MEDIUM4.3 MEDIUM
pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element.
CVE-2018-163306.1 MEDIUM4.3 MEDIUM
Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element.